Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Wall Street regulator lowers crypto focus for 2026 exams

The US Securities and Exchange Commission has removed its focus on crypto asset-related services from its list of examination priorities for Wall Street firms in the current fiscal year.

The SEC Division of Examinations will instead prioritize areas such as fiduciary duty, standards of conduct, asset custody, and new customer data privacy rules.

Unlike previous years, the latest annual statement does not include a dedicated section on cryptocurrency activity or digital asset volatility.

The fiscal year for the US government ends on September 30, 2026.

🔗 Source: Reuters

🧠 Food for thought

Implications, context, and why it matters.

Crypto exam shift may signal reclassification

  • FY2026 priorities lack a standalone crypto section. Oversight likely sits within custody (safeguarding client assets) and fiduciary duty (acting in clients’ best interests). It may also sit within standards of conduct or data privacy.
  • In 2025, exam priorities covered crypto assets 1. They named conduct standards and risk disclosures. They also covered operational resilience and security of blockchain-based assets.
  • SEC often weaves new risks into existing exams. Crypto reviews may now sit inside custody and conduct work as part of routine exams.

New data privacy rules create openings for compliance tech vendors

  • SEC is prioritizing new customer data privacy rules. Regulation S-P amendments require compliance by December 3, 2025, for larger broker-dealers (firms that trade securities for clients) and investment advisers (registered firms that manage client portfolios) 2. Vendors that offer incident response, breach notification, and customer data protection can pitch now.
  • The amendments require written incident response programs and a 30-day customer notification timeline for breaches. Service providers must alert covered institutions within 72 hours of detecting a breach 3. These rules create concrete technical needs that regtech (regulatory technology) and cybersecurity vendors can meet with purpose-built tools.
  • Investment advisers with $1.5 billion or more in Assets Under Management (AUM) and larger broker-dealers face the December 2025 deadline 4. Vendors should target firms that still need notification workflows and recordkeeping upgrades.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.